Method, apparatus and sofware for network traffic management
Abstract
A network traffic evaluation device is provided that may be used to warn of or prevent trafficabnormalities such as denial of service attacks. The device includes a data interface to receive one or both of network traffic and data indicative of characteristics f network traffic. The network traffic and/or data received by the data interface is processed for predeterminedcharacteristics that indicate that the network traffic contains a subset of attack traffic. Upon detection of the predetermined characteristics information defining a superset is provided. The superset is a portion of the network traffic that contains the subset and defines network traffic that may be redirected and/or blocked by a network device.
Claims
exact text as granted — not AI-modified1 . A traffic evaluation device including a data interface to receive one or both of network traffic and data indicative of characteristics of network traffic and including processing means operable to evaluate the network traffic and/or data received by said data interface for predetermined characteristics that indicate that the network traffic contains a subset of attack traffic, and upon detection of said predetermined characteristics retrieve from memory information defining a superset and provide an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device.
2 . The traffic evaluation device of claim 1 , wherein said output is in communication with the network device.
3 . The traffic evaluation device of claim 1 wherein said data interface is adapted to receive data from a plurality of network devices.
4 . The traffic evaluation device of claim 3 wherein and the processing means provides an output in communication with each network device capable of communicating a superset for the network device.
5 . The traffic evaluation device of claim 4 wherein the operation of said processing means to evaluate data received by said data interface for the presence of predetermined characteristics in said network traffic includes considering data from two or more network devices together.
6 . The traffic evaluation device of claim 1 wherein said data interface is further operable to receive network traffic from said network device, and dependent on any predetermined characteristics detected apply one or more filters to said network traffic to create filtered traffic and output said filtered traffic.
7 . The traffic evaluation device of claim 1 wherein said data interface is adapted to receive data from at least a first network device and a second network device and the processing means is operable to retrieve information defining the capabilities of said first and second network devices and if a smaller superset can be achieved by the second network device on data received by the first network device, provide on its output to the first network device instructions that cause it to forward traffic received by it to a second network device and instruct the second network device to redirect and/or block and/or filter the network traffic received from the first network device that is defined by the superset.
8 . The traffic evaluation device of claim 1 wherein the processing means is further operable to identify and assemble together packet fragments into a single packet and evaluate the assembled packet against said predetermined characteristics.
9 . The traffic evaluation device of claim 1 , wherein the predetermined characteristics include the existence of network traffic having predefined ratios of packets.
10 . The traffic evaluation device of claim 1 wherein the predetermined characteristics include a deviation between one or more current traffic parameters and one or more normal traffic parameters.
11 . The traffic evaluation device of claim 1 , wherein the processing means is operable to identify groups of data in said network traffic and evaluate each said group for said predetermined characteristics, wherein the predetermined characteristics used are dependent on the group.
12 . The traffic evaluation device of claim 9 , wherein the processing means is operable to identify groups of data in said network traffic and evaluate each said group for said predefined ratios, wherein the predefined ratios used are dependent on the group.
13 . A traffic evaluation device including a data interface to receive from a network device one or both of network traffic and data indicative of characteristics of network traffic and including processing means operable to separate the network traffic and/or data indicative of characteristics of network traffic received by said network interface into a plurality of groups and evaluate each group for predetermined characteristics that indicate that the group contains a subset of attack traffic.
14 . The traffic evaluation device of claim 13 , wherein upon detection of said predetermined characteristics, the processing means is further operable to retrieve from memory information defining a superset and provide an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device.
15 . Apparatus for monitoring network traffic for a traffic profile abnormality, the apparatus including data volume observing means for observing the volume of data communicated to or within a network and data classification means for classifying data communicated to or within the network into one or more of a plurality of classes and a processing means operable to:
a) for at least one pair of classes compute a ratio of:
observed data volume of one class or a function of observed data volume of one or more classes to
observed data volume of another class or a function of observed data volume of one or more other classes;
b) evaluate whether the one or more ratios indicate abnormal network traffic against predetermined criteria and if so output either or both of a signal indicating the potential occurrence of an attack.
16 . Apparatus as claimed in claim 15 wherein the processing means provide instructions to a network device to take predetermined action in response to an attack.
17 . Apparatus as claimed in claim 15 wherein the traffic profile abnormality includes a denial of service attack.
18 . The apparatus of claim 15 , wherein the processing means is further operable to compute at least one degree of abnormality, the or each degree of abnormality being a weighted function of one or more ratios and wherein each degree of abnormality is one of the one or more ratios that is evaluated in step b).
19 . The apparatus of claim 15 , wherein the processing means is further operable to upon detection of an attack retrieve from memory information defining a set of data that contains the attack traffic and provide an output defining said set defines network traffic that may be redirected and/or blocked by a network device.
20 . The apparatus of claim 15 wherein the processing means is further operable to identify and assemble together packet fragments into a single packet and evaluate the assembled packet against said predetermined criteria.
21 . A method of network traffic management including using a computer processing means to evaluate network traffic for predetermined characteristics that indicate that the network traffic contains a subset of attack traffic and upon detection of said predetermined characteristics retrieving from memory a superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device and communicating said superset to the network device.
22 . The method of claim 21 including evaluating for predetermined characteristics network traffic from two or more network devices together.
23 . The method of claim 21 wherein upon detection of said predetermined characteristics the method further includes directing said network device to redirect certain traffic to the computer processing means, and using the computer processing means to apply one or more filters to said network traffic to create filtered traffic and return said filtered traffic to the network device.
24 . The method of claim 21 wherein the predetermined conditions include the existence of network traffic having predefined ratios of packets.
25 . The method of claim 21 further including using the processing means to identify groups of data in said network traffic and evaluating each said group for said predetermined characteristics, wherein the predetermined characteristics used are dependent on the group.
26 . The method of claim 24 further including using the processing means to identify groups of data in said network traffic and evaluate each said group for said predefined ratios and wherein the predefined ratios used are dependent on the group.
27 . A method of managing network traffic including using a processing means to separate network traffic received by a network device or data indicating characteristics of network traffic received by a network device of into a plurality of groups and evaluating each group for predetermined characteristics that indicate that the group contains a subset of attack traffic and upon detection of said predetermined characteristics, retrieving from a memory information defining a superset and communicating to a network device that receives the network traffic an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by the network device.
28 . A method of monitoring network communication for a network traffic abnormality, the method including
a) observing the volume of data communicated to or within a network; b) classifying data communicated to or within the network into one or more of a plurality of classes; c) using a computer processing means, compute for at least one pair of classes a ratio of:
observed data volume of one class or a function of observed data volume of one or more classes to
observed data volume of another class or a function of observed data volume of one or more other classes;
d) evaluate whether the one or more ratios indicate abnormal network traffic against predetermined criteria and if so output either or both of a signal indicating the potential occurrence of an abnormality or instructions to a network device to take predetermined action in response to the abnormality.
29 . The method of claim 28 further including using said computer processing means to compute at least one degree of abnormality, wherein the or each degree of abnormality is a weighted function of one or more ratios and evaluating the degree of abnormality as one of said one or more ratios.
30 . The method of claim 28 wherein the step of monitoring for a network traffic abnormality includes the step of monitoring for a denial of service attack.
31 . Apparatus for monitoring network traffic for a traffic profile abnormality, the apparatus including historical traffic data gathering means to provide at least one selected normal traffic parameter, observing means for observing the current traffic data relating to the selected parameter to provide at least one current traffic parameter, and evaluating means to evaluate a deviation between the normal traffic profile parameter and the current traffic profile parameter against a threshold to determine whether a traffic abnormality exists.
32 . Apparatus as claimed in claim 31 wherein the selected parameter includes a plurality of parameters.
33 . Apparatus as claimed in claim 32 wherein the evaluating means evaluates a-weighted sum of the deviations.
34 . A method of monitoring network traffic for a traffic profile abnormality, the method including the steps of gathering traffic data to provide at least one selected normal traffic parameter, observing the current traffic data relating to the selected parameter to provide at least one current traffic parameter, and evaluating a deviation between the normal traffic profile parameter and the current traffic profile parameter against a threshold to determine whether a traffic abnormality exists.
35 . A method as claimed In claim 34 including the step of selecting a plurality of parameters.
36 . A method as claimed in claim 35 including the step of evaluating a weighted sum of the deviations.
37 . Any novel feature or combination of features disclosed herein.Join the waitlist — get patent alerts
Track US2005125195A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.